VENOM: QEMU vulnerability (CVE-2015-3456)

Status
Not open for further replies.

BootLayer

Member
5
2014
3
0
We just got notification that there is a critical QEMU bug that may affect KVM and XEN-HVM virtual machines.
According to Redhat:
A privileged guest user could use this flaw to crash the guest or, potentially, execute arbitrary code on the host with the privileges of the host's QEMU process corresponding to the guest. It needs to be noted that even if a guest does not explicitly have a virtual floppy disk configured and attached, this issue is exploitable. The problem exists in the Floppy Disk Controller, which is initialized for every x86 and x86_64 guest regardless of the configuration and cannot be removed or disabled.

https://access.redhat.com/articles/1444903

In short, attackers may gain full access to the Hypervisor and thus, full access to other virtual servers.
 
1 comment
Status
Not open for further replies.
Back
Top